Malware · 149 giorni fa
Phone Link trasforma un PC Windows compromesso in una trappola per credenziali. Se il desktop è sotto controllo dell’attaccante, questi può estrarre SMS e OTP rispecchiati dai dati di sincronizzazione locali senza toccare il telefono, quindi il consueto modello “proteggere il telefono” non coglie il vero perimetro di fiducia.
5 fonti che coprono questa storia
CloudZ Malware Abuses Phone Link to Steal SMS OTPs
Cisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPs
Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA
Attackers are dropping the CloudZ RAT and a fresh plug-in, Pheno, to hijack the Windows-based bridge between PCs and smartphones.
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
CloudZ RAT exploits Phone Link since Jan 2026, stealing credentials and OTPs via Pheno plugin, bypassing 2FA protections.
CloudZ RAT potentially steals OTP messages using Pheno plugin
Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.”
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-05